maintenance #
Backup of /mnt/Cofrin to an S3-compatible bucket using restic. Runs at 06:00 and 18:00.
Deploy to the cluster:
kubectl apply -f apps/maintenance/
One-off secret creation from host .env:
kubectl create secret generic backup-env \
--namespace=maintenance \
--from-env-file=/mnt/Cofrin/backup/.env
All backups are client-side encrypted by restic (AES-256). The .env file must contain RESTIC_REPOSITORY (e.g. s3:https://<endpoint>/<bucket>), RESTIC_PASSWORD, AWS_ACCESS_KEY_ID, and AWS_SECRET_ACCESS_KEY.
On failure the program sends a message to a Nextcloud Talk conversation via a bot. NEXTCLOUD_TALK_SECRET (bot shared secret) and NEXTCLOUD_TALK_TOKEN (conversation token from the URL /call/{token}) must be in the .env file. NEXTCLOUD_URL is set in the CronJob manifest.
Databases are dumped with dedicated tools (pg_dump, mariadb-dump, sqlite3 .backup) before each snapshot. Dump configs live in apps/maintenance/dbs.yaml and reference the database .env files on the host directly (no credential duplication). Raw database files are excluded from the snapshot; the dumps are part of it.